NIS2 for Critical Communications: Professor Kai London on Meeting the New Resilience Standard

 

By the Finnish Express Technology Desk

Professor Kai London, senior CISO and cybersecurity, AI and quantum computing expert
Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com

The second Network and Information Security Directive has raised the bar for essential-service operators across Europe, and telecoms sits squarely within its scope. “NIS2 is not IT paperwork,” says Professor Kai London, a senior CISO and board advisor. “It puts personal accountability for cyber resilience on senior management — and for communications providers, the obligations are significant.”

“The regulator's question has changed from ‘do you have a policy?’ to ‘can you prove it worked?’ For critical communications, that is the whole shift.”

What NIS2 requires

London distils the directive into a few operational demands: risk management proportionate to the threat, prompt incident reporting within tight timeframes, supply-chain security, and management accountability. “Essential and important entities must demonstrate resilience,” he says, “not merely assert it.”

Management on the hook

The feature London stresses is accountability. “Senior management must approve and oversee cyber-risk measures and can be held liable for failures,” he notes. “That is a deliberate move to put critical-infrastructure risk where it belongs — on the board.”

Supply chain and reporting

For communications providers dependent on a global equipment supply chain, London highlights third-party risk and rapid reporting as the hardest parts. “Know the suppliers you cannot live without, and be able to detect and report an incident within the required window,” he advises.

Compliance as capability

London reframes the directive as a specification for resilience the sector already needs. “A provider that can prove it will keep the network running through a crisis has an advantage,” he says. He recommends mapping critical services and dependencies, building incident detection and reporting to meet the timelines, and testing under realistic conditions.

For communications operators, London's message is that NIS2 describes the resilience society already expects — and meeting it, provably, is both a duty and a differentiator.


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Popular posts from this blog

Post-Quantum Cryptography and the Future of Secure Communications: Professor Kai London Explains

The Invisible Airborne Perimeter: Professor Kai London on Wireless Threats and Nation-State Actors

Interim and Fractional CISO Leadership: Professor Kai London on Board-Grade Security at Speed